 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1: l5 L( v# y6 `
Scan saved at 16:55:24, on 2006-5-6
2 b4 y- ?1 _ ~# n' sPlatform: Windows XP SP2 (WinNT 5.01.2600)
6 j3 V; m* H9 _MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* y, ^( c7 b1 {
1 h- j; W* d% ]8 H @9 S% L% \Running processes:
( ?, M# C3 V: y) `+ }% q' U, t8 D' |C:\WINDOWS\System32\smss.exe
8 y) u' G9 f7 E8 h, Q6 O9 ?C:\WINDOWS\system32\winlogon.exe$ S7 p$ p; I+ U' Z" T& g( K
C:\WINDOWS\system32\services.exe
9 s# m& N/ V. i1 c% e! gC:\WINDOWS\system32\lsass.exe
, E' J$ I$ T* P1 b. [! XC:\Program Files\Common Files\Virtual Token\vtserver.exe2 {; L( m: Z. E% C& X
C:\WINDOWS\system32\ibmpmsvc.exe' t+ b* \; ?, `
C:\WINDOWS\system32\svchost.exe5 K1 t0 d O3 C: z
C:\WINDOWS\System32\svchost.exe; p1 p) \' [$ y7 I. n/ \# a; z* U( X
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
- T, {' @! p9 ~8 |C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
6 z: y6 t" @: q. e2 yC:\WINDOWS\system32\spoolsv.exe
* L% y$ @0 H+ P: f& GC:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE+ K# `9 |+ c' {
C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
, m$ B" i- k) L2 xC:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
8 @% E8 M2 k D ^" RC:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
- h( K/ l& A; M6 D' e/ {8 rC:\Program Files\F-Secure\Common\FSMA32.EXE
- P1 G* |) j0 Z' FC:\Program Files\F-Secure\Common\FSMB32.EXE# K1 Q V4 i( c6 v" \/ f
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
% A& e$ i$ |! O! EC:\Program Files\F-Secure\Anti-Virus\fssm32.exe
) D% P3 Q: a- Q) w- H1 w: HC:\WINDOWS\System32\QCONSVC.EXE
4 W9 Q1 V% |9 @3 Y& H6 jC:\Program Files\F-Secure\Common\FCH32.EXE
" U0 u) Y2 ]* m% [1 g1 K! ]# X1 i4 FC:\Program Files\Intel\Wireless\Bin\RegSrvc.exe; }, ~, J% y6 }+ a$ S, [
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
, c) @' k& C; C# w" RC:\WINDOWS\System32\TPHDEXLG.EXE' ~) W$ R+ c* v0 P; R" T6 T
C:\Program Files\F-Secure\Common\FAMEH32.EXE) q7 s' a: }% Z+ Y
C:\WINDOWS\system32\TpKmpSVC.exe
& I, E3 i; o" xC:\Program Files\F-Secure\Anti-Virus\fsqh.exe7 O7 S8 N! H3 W, a9 m. r
C:\Program Files\F-Secure\Anti-Virus\fsrw.exe
# h t$ ^, K5 }6 o* YC:\Program Files\F-Secure\Common\FNRB32.EXE& q+ F, N& j' Z3 p# U
C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
. M/ w# g3 Y; VC:\Program Files\F-Secure\Common\FIH32.EXE# k, L3 k. k8 ?; M; F$ @8 }
C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
& g+ ]+ y/ b7 D- RC:\WINDOWS\Explorer.EXE
7 b G4 D, Q0 g! D& p4 b$ b F6 H t, HC:\Program Files\Synaptics\SynTP\SynTPLpr.exe
8 Z" o' |8 V' d' W b3 N+ X) J- p5 VC:\Program Files\Synaptics\SynTP\SynTPEnh.exe
/ i5 }' |: ^" i- p" ]/ P* V9 O! R9 g; VC:\WINDOWS\system32\hkcmd.exe c2 P6 S$ @1 i5 C
C:\WINDOWS\system32\TpShocks.exe
, x$ ^( Z1 }5 W7 TC:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
8 F& R9 N' c* MC:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe& [+ E- x' \' a" V
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe! ^7 f4 M$ b0 r! M9 C0 J
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe' w& B+ m, Y8 t+ t8 ~+ F$ Y f' T4 t
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
6 E' |# }+ N6 A7 ?5 ^C:\WINDOWS\system32\dla\tfswctrl.exe
# z6 j3 V, f1 n; D! _8 O7 gC:\Program Files\IBM\Messages By IBM\ibmmessages.exe
! l/ y- N, {. c1 r4 E0 u+ U8 x* @C:\IBMTOOLS\UTILS\ibmprc.exe
. G+ i% h0 x- p g* ?2 kC:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE. B9 t' i9 j$ c' n+ e
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
0 b0 | l! x: I! yC:\WINDOWS\System32\svchost.exe' F" @, v5 u/ E7 E' W& W
C:\WINDOWS\system32\rundll32.exe
6 m' j: M B4 \3 _% o- P5 T: JC:\Program Files\F-Secure\Common\FSM32.EXE3 T4 O' ^( V* X2 k D( c+ V( G% T
C:\WINDOWS\system32\CTFMON.EXE+ t9 V8 a2 [& U5 p {- a
C:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
& ~+ T5 n# F: p; sC:\Program Files\Digital Line Detect\DLG.exe
( ?' \, K. k; H2 w+ x8 p; XC:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe1 a% B4 j3 m- R: L& a
C:\Program Files\F-Secure\FSGUI\fsguidll.exe
2 ]# V* e- r8 x( FC:\Program Files\Messenger\msmsgs.exe2 T& T O; {( q( \$ G
C:\Program Files\Internet Explorer\iexplore.exe
; U* g6 _8 \( g6 f+ \9 A) M# R$ j. ^C:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe7 d% Z) F4 R4 `8 Q
* o% q& y$ ?3 X+ o+ z: ^* |' b
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll1 p! o- ^% k/ M+ j5 N& ^
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe% a) i* _+ w+ Q8 X8 @
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe! o# L. @% m+ `9 b; w- g3 p f: P
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe* J. ~% w2 B1 c; K
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe9 J. D4 z" I% _5 @3 J4 A# `2 H
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
6 ^$ m) T% f; F3 I' pO4 - HKLM\..\Run: [TpShocks] TpShocks.exe
- | ~' t9 I1 C: TO4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe% S" k! P: t6 x7 O* C/ _( X9 a# }
O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup
- R, f* v( v* u; a' `O4 - HKLM\..\Run: [TP4EX] tp4ex.exe7 o6 I! e+ M1 A- ?
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe9 t7 h" ^+ Y- n; W
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
7 d9 t; X' ^) d$ k0 e8 C6 OO4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
K E) {- d& G4 a" {O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r# [7 S* Q( q; Z$ S* s. u
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
% N1 W( s# R& G# b- J4 ~O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe
0 L5 J8 r2 p- q+ UO4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe
/ O# B& Z" G- X$ c7 CO4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
# z( o9 t; O' x- JO4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE' E1 ^$ Z/ K9 T( y
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
# N. L9 d. }0 `. O9 a9 `O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
5 L( v2 f' b( yO4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32+ w6 ?1 K+ z& p5 T6 U6 ?9 U
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
# X! E9 m! n2 Q, |& K1 ~+ RO4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC: o# t3 k7 s/ r9 S, R1 u: G- Y
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC" i- U7 J$ I" y' f8 W; Y
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName) Z5 W+ q- p$ R# \
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
Q5 F. f) P) y2 LO4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
5 V4 L) _+ d& X# ~# A( S. ?% r' RO4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe4 K. [2 O5 B6 T
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe! s! y: R; ?+ I5 g8 u+ V! c
O4 - Global Startup: Digital Line Detect.lnk = ? G7 O; H' H9 ?5 \- i1 w- T. n/ Z& b
O4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe& I5 C" |8 |; ?1 U4 o: p' I
O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm
2 r' K7 z2 h$ dO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
% @1 r& L( K6 [$ o) G5 zO9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
' p/ ]% ?0 `6 JO9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
( `' Z. O3 p, a' b2 w6 Z* g7 Q& _O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
/ N: V( _$ a' q- s7 M, i( q M- VO9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe1 V3 o L" T2 Z1 u
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
( ]* G! f! H9 E' U! B; S/ }- EO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
' z! b& g4 p2 x7 b+ iO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
; D0 t- }4 ?6 kO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll( @ y* D8 I0 t2 q9 p
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
z0 v7 r7 I) U+ ~) ]O11 - Options group: [JAVA_IBM] Java (IBM)
" b$ N1 _* T, I9 ]O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
3 G# \7 V$ X7 NO20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll& X5 p. v* P7 i, x% T- z+ ]
O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll
5 S8 k+ @; D- y$ A- b$ iO20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
7 c, Q: @+ k* s% I# KO23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE o! }4 Z4 }5 |5 d
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe. ]! j( H$ s# B5 L$ \' _ v
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
) {4 k# w' I1 c4 a# v2 q- y; O8 nO23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
. U+ _2 Z1 }& a* CO23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
" q* R% G5 I" U6 |" p, Z) YO23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe9 U% r8 N5 S+ Z! g) j1 f4 H
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
+ E* C9 h d( }, D, Z- dO23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe8 G1 g4 P: R+ L* a% j
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
: g, J! _9 `' {O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe8 m: @: R* \0 s3 ?- \
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
- p+ Q6 ]. U& C3 _9 M1 a6 E$ ?: mO23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
* ^. c* B9 q5 t: IO23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
6 O1 P- I1 l& }5 O; hO23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe" O( [9 N% Z0 p
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe9 C) A4 b4 d- h) C/ o
O23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE
4 D# o4 @& a1 C: Y# KO23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
4 r; m. |* `+ l3 [2 N& wO23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|